CVE-2021-20233
published 2021-03-03CVE-2021-20233: A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that…
PriorityP339high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
EPSS
0.61%
45.2th percentile
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | < grub2 2.04-16 (bookworm) | grub2 2.04-16 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | grub2 | < 2.06 | 2.06 |
| gnu | grub2 | — | — |
| gnu | grub2 | >= 0 < 2.04-16 | 2.04-16 |
| gnu | grub2 | >= 0 < 2.04-16 | 2.04-16 |
| gnu | grub2 | >= 0 < 2.04-16 | 2.04-16 |
| gnu | grub2 | >= 0 < 2.04-16 | 2.04-16 |
| msrc | azl3_grub2_2.06-26_on_azure_linux_3.0 | — | — |
| msrc | cbl2_grub2_2.06rc1-7_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.2HIGH
vendor_debian8.2HIGH
vendor_msrc8.2HIGH
vendor_redhat8.2HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-257g-8w4g-3cc3: A flaw was found in grub2 in versions prior to 2
ghsa_unreviewed·2022-05-24
CVE-2021-20233 [HIGH] CWE-787 GHSA-257g-8w4g-3cc3: A flaw was found in grub2 in versions prior to 2
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
OSV
grub2-signed, grub2-unsigned vulnerabilities
osv·2021-06-18·CVSS 7.5
CVE-2020-14372 [HIGH] grub2-signed, grub2-unsigned vulnerabilities
grub2-signed, grub2-unsigned vulnerabilities
Máté Kukri discovered that the acpi command in GRUB 2 allowed privileged
users to load crafted ACPI tables when secure boot is enabled. An attacker
could use this to bypass UEFI Secure Boot restrictions. (CVE-2020-14372)
Chris Coulson discovered that the rmmod command in GRUB 2 contained a use-
after-free vulnerability. A local attacker could use this to execute
arbitrary code and bypass UEFI Secure Boot restrictions. (CVE-2020-25632)
Chris Coulson discovered that a buffer overflow existed in the command line
parser in GRUB 2. A local attacker could use this to execute arbitrary code
and bypass UEFI Secure Boot restrictions. (CVE-2020-27749)
It was discovered that the cutmem command in GRUB 2 did not honor secure
boot locking. A local attack
OSV
CVE-2021-20233: A flaw was found in grub2 in versions prior to 2
osv·2021-03-03·CVSS 8.2
CVE-2021-20233 [HIGH] CVE-2021-20233: A flaw was found in grub2 in versions prior to 2
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CISA ICS
Hitachi Energy APM Edge (Update A)
cisa_ics·2021-12-02·CVSS 9.1
[CRITICAL] Hitachi Energy APM Edge (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy APM Edge (Update A)
Last RevisedOctober 18, 2022
Alert CodeICSA-21-336-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Low attack complexity
- Vendor: Hitachi Energy
- Equipment: Transformer Asset Performance Management (APM) Edge
- Vulnerability: Reliance on Uncontrolled Component
## 2. UPDATE OR REPOSTED INFORMATION
This updated advisory is a follow-up to the original advisory titled “ICSA-21-336-06 Hitachi Energy APM Edge” that was published December 02, 2021, on the ICS webpage on cisa.gov/ics.
## 3. RISK EVALUATION
Successful exploitation of thi
Ubuntu
GRUB 2 vulnerabilities
vendor_ubuntu·2021-06-18·CVSS 7.5
CVE-2021-20225 [HIGH] GRUB 2 vulnerabilities
Title: GRUB 2 vulnerabilities
Summary: Several security issues were fixed in GRUB 2.
Máté Kukri discovered that the acpi command in GRUB 2 allowed privileged
users to load crafted ACPI tables when secure boot is enabled. An attacker
could use this to bypass UEFI Secure Boot restrictions. (CVE-2020-14372)
Chris Coulson discovered that the rmmod command in GRUB 2 contained a use-
after-free vulnerability. A local attacker could use this to execute
arbitrary code and bypass UEFI Secure Boot restrictions. (CVE-2020-25632)
Chris Coulson discovered that a buffer overflow existed in the command line
parser in GRUB 2. A local attacker could use this to execute arbitrary code
and bypass UEFI Secure Boot restrictions. (CVE-2020-27749)
It was discovered that the cutmem command in GRUB 2 did not
Microsoft
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 c
vendor_msrc·2021-03-09·CVSS 8.2
CVE-2021-20233 [HIGH] CWE-787 A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 c
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
Red Hat
grub2: Heap out-of-bounds write due to miscalculation of space required for quoting
vendor_redhat·2021-03-02·CVSS 8.2
CVE-2021-20233 [HIGH] CWE-787 grub2: Heap out-of-bounds write due to miscalculation of space required for quoting
grub2: Heap out-of-bounds write due to miscalculation of space required for quoting
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
A flaw was found in grub2. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt me
Red Hat
grub2: heap out-of-bound write due to mis-calculation of space required for quoting
vendor_redhat·2021-03-02·CVSS 8.2
CVE-2021-3408 [HIGH] CWE-787 grub2: heap out-of-bound write due to mis-calculation of space required for quoting
grub2: heap out-of-bound write due to mis-calculation of space required for quoting
[REJECTED CVE] The grub2 menu rendering code miscalculate the memory amount to hold single-quoted strings. This lead to a out-of-bounds write in grub2's heap by one byte per quote in the input. This results to a 'write-what-where' scenario which an attacker may leverage to compromise heap integrity and possibly code execution, leading to Secure Boot circumvention. To an attack being successful deployed, the attacker needs to have high privileges into the targeted system and also triage the heap layout to successfully deploy a crafted payload.
Statement: This flaw was found to be a duplicate of CVE-2021-20233. Please see https://access.redhat.com/security/cve/CVE-2021-20233 for information about affected p
Debian
CVE-2021-20233: grub2 - A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the me...
vendor_debian·2021·CVSS 8.2
CVE-2021-20233 [HIGH] CVE-2021-20233: grub2 - A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the me...
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Scope: local
bookworm: resolved (fixed in 2.04-16)
bullseye: resolved (fixed in 2.04-16)
forky: resolved (fixed in 2.04-16)
sid: resolved (fixed in 2.04-16)
trixie: resolved (fixed in 2.04-16)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1926263https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWZ36QK4IKU6MWDWNOOWKPH3WXZBHT2R/https://security.gentoo.org/glsa/202104-05https://security.netapp.com/advisory/ntap-20220325-0001/https://bugzilla.redhat.com/show_bug.cgi?id=1926263https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWZ36QK4IKU6MWDWNOOWKPH3WXZBHT2R/https://security.gentoo.org/glsa/202104-05https://security.netapp.com/advisory/ntap-20220325-0001/
2021-03-03
Published